---
title: "Fortanix DSM with AppViewX CLMaaS"
slug: "fortanix-dsm-with-appviewx-clmaas"
updated: 2026-07-08T17:21:55Z
published: 2026-07-08T17:21:55Z
canonical: "support.fortanix.com/fortanix-dsm-with-appviewx-clmaas"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with AppViewX CLMaaS

## 1.0 Introduction

The integration between appviewX and Fortanix helps enterprises overcome the challenges brought by managing private keys in a complex infrastructure. appviewX acts as the automation and orchestration engine for the lifecycle management of X.509 certificates, and Fortanix-Data-Security-Manager (DSM) ensures the security of the private keys associated with those certificates in the cloud, on-premises or as a hybrid solution.

## 2.0 Prerequisites

Ensure the following:

- The **avx_platform_hsm** plugin should be up and running in the appviewX cluster.

If not, follow the steps given in [*Section 4.0 Integration Fortanix HSM with appviewX CLMaaS*](/v1/docs/using-fortanix-data-security-manager-with-appviewx-clmaas#40-integration-fortanix-hsm-with-appviewx-clmaas) to enable this plugin.

## 3.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 3.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to the* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 3.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 1: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to the* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

### 3.3 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(38).png)

**Figure 2: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 3.4 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(37).png)

**Figure 3: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 4.3: Creating a Group*](/v1/docs/using-fortanix-data-security-manager-with-appviewx-clmaas#33-creating-a-group) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#43-creating-a-group)from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 3.5 Copying the API Key

Perform the following steps to copy the API key from the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 3.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-appviewx-clmaas#34-creating-an-application) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#44-creating-an-application)to go to the detailed view of the app.
2. On the **INFO** tab, click **VIEW API KEY DETAILS**.
3. From the **API Key Details** dialog box, copy the **API Key** of the app to use it later in **Vendor specific details** in [*Section 4.0: Integrating Fortanix HSM with AppViewX CLMaas*](/v1/docs/using-fortanix-data-security-manager-with-appviewx-clmaas#40-integration-fortanix-hsm-with-appviewx-clmaas).

## 4.0 Integrate Fortanix HSM with AppViewX CLMaaS

The following are the steps to integrate Fortanix DSM with appviewX CMLSaaS:

1. Make sure appviewX cloud connector is installed in your network. Communication from appviewX to Fortanix HSM will be routed through this cloud connector.
2. Log in to the appviewX UI using valid credentials. By default, the Dashboard is displayed.
3. From the top-right corner of the Dashboard, click ![DeviceIcon.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/deviceicon.png).
4. From the menu displayed, select **Inventory** → **Device**.

![AppViewX-Device.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/appviewx-device.png)

**Figure 4: aapviewX Dashboard**

The **Device :: ADC** page is displayed.
5. Under the **HSM** tab, from the navigation pane on the left, select **Fortanix**.

![AppViewX-HSMDevice.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/appviewx-hsmdevice.png)

**Figure 5: Fortanix HSM device**
6. In the **General Information** section, enter/select the following details:
  - **Name***: Enter a name for this integration.
  - **Description**: Enter a description for the integration.
  - **Implementation** **type**: Select the implementation type.
  - **Data center***: From the drop down list, from the list of applicable values, select the required data center.

> [!NOTE]
> NOTE
> 
> The data center selected here is used to map the appviewX Cloud Connector for this integration.
7. In the **Vendor specific details** section, enter/select the following details:
  - **API Key***: Fortanix DSM app credentials.
  - **Key handler name***: A reference name to create a Master Encryption key in HSM. This enables us to pick the right MEK for crypto operations over KEK.
  - **So file location***: The SO file is used to facilitate the communication between the HSM and appviewX. To upload the `.so` file:
    1. Click **Browse**.
    2. Navigate to the location of the `.so` file.
    3. Select the `.so` file and click **Open**.
  - **Config file location**: The Config file is used to facilitate the communication between the HSM and appviewX. To upload the `.conf` file:
    1. Click **Browse**.
    2. Navigate to the location of the `.conf` file.
    3. Select the `.conf` file and click **Open**.
8. Click **Save**.
9. Scroll to the end of this page to view the table that will be populated with all the details of this HSM. If the HSM has been configured correctly, the **Status** for the HSM will be set to **Available** (after checking the encryption and decryption logic). If the **Status** is **Not Available**:
  - Check the installation path for the HSM.
  - Ensure that all required permissions have been enabled.
10. If the implementation type is **CSR Generation**, to generate the CSR, follow the steps given here:
  - [*Server certificate*](https://adminguide.appviewx.com/server-certificate-enrollment-5)
  - [*Client certificate*](https://adminguide.appviewx.com/client-certificate-enrollment-4-2)
  - [*Code signing certificate*](https://adminguide.appviewx.com/code-signing-certificate-enrollment-4-2)

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.
